<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Secure connection for firewall web GUI in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/secure-connection-for-firewall-web-gui/m-p/444026#M100285</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I want to make a secure connection for the firewall GUI access. therefore I perform the below task:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I imported the wildcard certificate in the firewall and the same certificate attached in SSL/TLS profile ( This is 3rd party certificate get by DigiCert).&lt;/P&gt;&lt;P&gt;Then the SSL/TLS profile is configured for management settings.&lt;/P&gt;&lt;P&gt;for troubleshooting purposes, i imported the certificate into the client machine as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did the above configuration and access to the firewall with a different browser like&amp;nbsp; - IE, chrome, edge, firefox but all browser is showing the connection is not secure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two doubts:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;1- My wild certificate name is &lt;STRONG&gt;abc.com.jk&lt;/STRONG&gt; which resolves my internal DNS &lt;STRONG&gt;10.10.10.10&lt;/STRONG&gt; and my management IP address is &lt;STRONG&gt;192.168.1.1&lt;/STRONG&gt; - Anything wrong with this or it is correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 - I noticed that the certificate that I received from DigiCert its not a CA below is the image for reference- &lt;STRONG&gt;The Certificate should be the CA to make a secure connection?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1635421220462.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37313i5B2FD98E98E5A244/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1635421220462.png" alt="Jafar_Hussain_0-1635421220462.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can anyone have suggestions on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Oct 2021 11:43:03 GMT</pubDate>
    <dc:creator>Jafar_Hussain</dc:creator>
    <dc:date>2021-10-28T11:43:03Z</dc:date>
    <item>
      <title>Secure connection for firewall web GUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-connection-for-firewall-web-gui/m-p/444026#M100285</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I want to make a secure connection for the firewall GUI access. therefore I perform the below task:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I imported the wildcard certificate in the firewall and the same certificate attached in SSL/TLS profile ( This is 3rd party certificate get by DigiCert).&lt;/P&gt;&lt;P&gt;Then the SSL/TLS profile is configured for management settings.&lt;/P&gt;&lt;P&gt;for troubleshooting purposes, i imported the certificate into the client machine as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did the above configuration and access to the firewall with a different browser like&amp;nbsp; - IE, chrome, edge, firefox but all browser is showing the connection is not secure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two doubts:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;1- My wild certificate name is &lt;STRONG&gt;abc.com.jk&lt;/STRONG&gt; which resolves my internal DNS &lt;STRONG&gt;10.10.10.10&lt;/STRONG&gt; and my management IP address is &lt;STRONG&gt;192.168.1.1&lt;/STRONG&gt; - Anything wrong with this or it is correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 - I noticed that the certificate that I received from DigiCert its not a CA below is the image for reference- &lt;STRONG&gt;The Certificate should be the CA to make a secure connection?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1635421220462.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37313i5B2FD98E98E5A244/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1635421220462.png" alt="Jafar_Hussain_0-1635421220462.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can anyone have suggestions on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 11:43:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-connection-for-firewall-web-gui/m-p/444026#M100285</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2021-10-28T11:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: Secure connection for firewall web GUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-connection-for-firewall-web-gui/m-p/444142#M100301</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Certificate warning could be caused by couple of reasons. It will be usefull to see the exact error that browser return - it should point you in correct direction. It could be either the issuer is not trusted, the address you use in the URL is not matching what is in the certificate, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I want to make some clarifications as it seems you make some wrong assumptions:&lt;/P&gt;
&lt;P&gt;- Certificate Authority (CA) certificate is need to validate the server certificate that server provide to you when you connect to it. In your case firewall is acting as server (because its web interface is actually a web server). Which means that your firewall needs a server certificate and the corresponding private key with it.&lt;/P&gt;
&lt;P&gt;- You don't have to import that certificate to the browser cert store. Again this certificate is the server cert that FW will send to you when you try to connect to it, in oder to validate its identity to you. So you need to know how to trust this information, which is the purpose of the CA. You what you need is the CA that has signed the server (firewall) cert to be in your browser Trusted Publisher/Root CA certificate store. Looking at your screenshot it seems you use public CA, that should already be trusted by all browsers.&lt;/P&gt;
&lt;P&gt;- I am bit confuse, because you said you use &lt;U&gt;wildcard certificate&lt;/U&gt; while you said the "wild certificate name is &lt;STRONG&gt;abc.com.jk&lt;/STRONG&gt;" Wildcard certificate should include a start "*" at the begining , like &lt;STRONG&gt;*.com.jk. &lt;/STRONG&gt;Can you explain a bit more what you ment as it possible that this is your reason for ssl warning&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 17:20:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-connection-for-firewall-web-gui/m-p/444142#M100301</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-10-28T17:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Secure connection for firewall web GUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-connection-for-firewall-web-gui/m-p/444558#M100362</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We import wild card certificate *.abc.com.jk.&lt;/P&gt;&lt;P&gt;one more test I did, I generate a self-sign certificate and attached in SSL /TLS profile then the same SSL/TLS profile configure for the Management Interface.&lt;/P&gt;&lt;P&gt;Then i found the login page was secure but i don't want to use the self-sign certificate. i want to use a 3rd party certificate but not able to find the cause of this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jafar Hussain&lt;/P&gt;</description>
      <pubDate>Sun, 31 Oct 2021 12:39:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-connection-for-firewall-web-gui/m-p/444558#M100362</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2021-10-31T12:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: Secure connection for firewall web GUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-connection-for-firewall-web-gui/m-p/444560#M100363</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If using self-signed certificate works without issues, I am guessing you are applying the correct steps.&lt;/P&gt;
&lt;P&gt;I am starting to believe that you have troubles with the "multilevel" wildcard certificate. This means that:&lt;/P&gt;
&lt;P&gt;- I you have wildcard for *.abc.com.jk, this certificate is valid for any host, but only for that level:&lt;/P&gt;
&lt;P&gt;- examples of hostnames from same level are: firewall.abc.com.jk, test.abc.com.jk, vpn.abc.com.jk&lt;/P&gt;
&lt;P&gt;- example of hostnames that will are not part of this sub-domain, and will give ssl error: west.firewall.abc.com.jk, abc.com.jk, zzz.com.jk, firewall.com.jk&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you certificate is *.abc.com.jk, what is the hostname you use for the fw mgmt? also - when you try to access the mgmt interface, are using the IP address or the FQDN in the web browsers addressbar?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Oct 2021 13:03:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-connection-for-firewall-web-gui/m-p/444560#M100363</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-10-31T13:03:52Z</dc:date>
    </item>
  </channel>
</rss>

